Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Jérôme Meyer

@jmeyer@infosec.exchange
  • Open on infosec.exchange

Security research at Nokia Deepfield (he/they).

EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

0 Followers
0 Following
19 Posts
Joined November 09, 2022
Homepage:
https://med.ac/about
Signal:
jmeyer.01
Work account:
https://infosec.exchange/@deepfield

Posts

Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Jul 24, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange
RE: https://infosec.exchange/@deepfield/116976577337745826 it infects your neighbour's router by guessing the telnet password and then politely asks your router to open 165 ports. one of those is a break in and the other is UPnP working exactly as designed. anyway it all comes back to one guy off a funding wallet and a config key he forgot to rotate. the cluster map is pepe silvia. this is my job.
Quoting
Nokia Deepfield @deepfield@infosec.exchange
New, from our ERT: Most residential proxy malware hides the exit behind an outbound tunnel. This one has the victim’s own router open 165 ports over UPnP and labels every mapping RELAY. Telemetry on the proxy domains led us back to #Jackskid, a DDoS botnet we have tracked since late 2025. Same operator behind all of it: a pure relay family, a Mirai bot that moonlights as one, and Jackskid, which now compiles the relay straight in. https://github.com/deepfield/public-research/blob/main/reports/2026-07-24-jackskid-residential-proxy-upnp.md #threatintel #tree4sale #peer4you
Open quoted post
0
0
0
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Jul 21, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange
RE: https://infosec.exchange/@deepfield/116959928537612450 “Not a mirai at all” it insists, from inside the mirai. the denial is honestly aspirational
Quoting
Nokia Deepfield @deepfield@infosec.exchange
New ERT report: #IranBot is a botnet built to be thrown away. Three builds in six weeks, no infrastructure reused, each one cruder and each one reaching further. The build stripped of encryption is the one worming today, and its C2 outlives none of the others by much. https://github.com/deepfield/public-research/blob/main/iranbot/report.md #threatintel #DDoS
Open quoted post
0
0
0
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Jul 11, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange
Replying to @kr3st3n@infosec.exchange
@kr3st3n@infosec.exchange Indeed — they recommend volunteers run this behind a VPN, so we indeed mostly see exit nodes from a handful of VPN providers, for the most part.
0
0
0
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Jul 05, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange
RE: https://infosec.exchange/@deepfield/116868970182801401 reversing the least threatening thing in my pipeline: they garbled the Go, hand-edited the headers, made it genuinely annoying in ghidra. it worked! it stopped me for a weekend! to reach a target list i’ve had a live feed of for YEARS the decryption key was a cookie they sent me. anyway
Quoting
Nokia Deepfield @deepfield@infosec.exchange
DDoSia is one of the least interesting botnets we track. We wrote it up anyway. Its product was never downtime. It’s the claim of downtime. We looked at the actual traffic. The honest version is boring. And boring is the one story the group can’t turn into a win. New from our ERT: https://github.com/deepfield/public-research/blob/main/ddosia/report.md #threatintel #NoName057
Open quoted post
0
1
0
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Jul 04, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange
RE: https://infosec.exchange/@deepfield/116863154478881362 The part that didn’t make the report: nobody tipped us off. This was in our own telemetry the whole time and we, professionals, scrolled past it for months. one operator, two fleets, floods tasked through the proxy’s own 0x07 the entire time. Anyway nothing says “legitimate residential proxy” like calmly issuing an attack command against a full /15 of some ISP, totally normal, nothing to see, scroll on
2
0
1
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · May 02, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange
Replying to @jmeyer@infosec.exchange
@campuscodi @censys also notes in https://censys.com/blog/the-cpanel-situation-is/ that this may be related to a Mirai-derivative we have been tracking under Flameblox. I should be able to confirm that with the next attack commands.
0
0
0
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Apr 30, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange
Replying to @campuscodi@mastodon.social
@campuscodi@mastodon.social Saw a ~6 Tbps attack this morning with about 5k hosting sources, which had one thing in common: cPanel
5
2
4
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Apr 13, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange
Replying to @hrbrmstr@mastodon.social
@hrbrmstr congratulations on the new job! (And welcome to the Ann Arbor nexus)
1
0
0
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Apr 12, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange

New report from our ERT: #Maskify.

The operator built what a Series A deck would call "decentralized edge infrastructure": ENS for service discovery, IPFS for binary distribution, a custom P2P mesh network, QUIC transport.

In practice it is a DDoS botnet running on Android TV boxes that did not opt in.

https://github.com/deepfield/public-research/blob/main/maskify/report.md

#threatintel #ddos

1
0
0
1
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Apr 08, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange

When a botnet operator names their payload after your team, you check the diff.

libcyn.so → deepfield.so
Custom cipher → wolfSSL TLS 1.3 (same stack as earlier Kimwolf)

C2 domains, floods, targets: all unchanged.

9a28696774d9ef6754540633daeef668767df5efa1804138abd35e1a6b31523e

#drifter #threatintel #ddos

1
0
0
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Apr 03, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange

The backstory of #Kimwolf, from our initial sightings early last year to how @synthient@cyberplace.social discovered the vuln that made that botnet possible.

https://www.wsj.com/tech/kimwolf-hack-residential-proxy-networks-a712ab59?st=3eNTjx

2
2
0
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Mar 28, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange

New, from our @deepfield@infosec.exchange ERT: found a new botnet dressing its C2 traffic as camera management.

#Drifter names its domains after Hikvision products, blending with surveillance traffic on the same VLAN as the Android TV boxes it infects. DNS queries go through an Australian resolver, which somewhat undermines the cover if your bot is in São Paulo.

71 KB binary, already linked to attacks exceeding 2 Tbps from 80k sources. At least six operators are now competing for the same devices.

https://github.com/deepfield/public-research/blob/main/drifter/report.md

#threatintel #ddos

8
0
6
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Mar 24, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange
Replying to @CyberPhilTrem@infosec.exchange
@CyberPhilTrem@infosec.exchange 3 Vallées 💯
1
0
0
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Mar 24, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange

Other than publishing these botnet reports I’m enjoying my week off 🤣

3
2
0
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Mar 24, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange

RE: @deepfield@infosec.exchange

The operator built triple-layer crypto, fast-flux DNS across 30+ ASes, biweekly C2 rotation — then shipped an unstripped debug build on port 8090, a couple of ports over from production. 300+ symbols, project name, internal module names, all right there in readelf.

Anyway here's the full writeup.

https://github.com/deepfield/public-research/blob/main/jackskid/report.md

#threatintel #ddos

20
0
14
2
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Mar 21, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange

New, from our ERT: #CECbot, an Android TV botnet and the first malware we're aware of that exploits HDMI-CEC.

It puts the TV to sleep so you don't notice the box behind it is running DDoS and residential proxy traffic. Curve25519/ChaCha20 crypto, 9 persistence layers, and... LAN mapping.

Successor to a Mirai fork, shares not much but the C2 server.

https://github.com/deepfield/public-research/blob/main/cecbot/report.md

#threatintel #DDoS

12
0
13
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Mar 20, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange

One custom RC4 seed led us to four botnets, five C2 channels, and a developer who shipped their Windows username and Cursor IDE logs with their malware.

Equal parts cryptography, thread-pulling, and easter eggs.

https://github.com/deepfield/public-research/blob/main/reports/2026-03-20-aisuru-ecosystem.md

#threatintel #Aisuru #kimwolf #jackskid #mossadproxy #cecilio

16
0
6
1
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Mar 19, 2026
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange

RE: @deepfield@infosec.exchange

We dug into the binaries from a Xiongmai DVR proxyware campaign that @nicter_jp@bird.makeup wrote up. Mirai stripped for parts, PacketSDK with a dead dispatch chain, and a dormant RCE backdoor that's just... waiting.

Our report (which really is a companion piece to NICTER's): https://github.com/deepfield/public-research/blob/main/reports/2026-03-19-xiongmai-packetsdk-ipidea.md

#threatintel #IPIDEA

2
0
0
0
Open post
jmeyer
Jérôme Meyer @jmeyer@infosec.exchange · Mar 04, 2025
Jérôme Meyer
@jmeyer@infosec.exchange

Security research at Nokia Deepfield (he/they). EN/FR posts | Fan of Crocker’s Rules, art, and the Oxford comma.

infosec.exchange
Replying to @shadowserver@infosec.exchange
@shadowserver @deepfield Thanks for the additional analysis, this is great. This lines up pretty well with what we’re seeing for bot counts (the deviation on Taiwan may be related to a slightly different device signature, looking into that now). Current count is approx 41k bots seen in attacks so far.
2
0
1
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:18:15 UTC